pypi

web3socket @0.1.4

Vulnerability report · Last retrieved from osv.dev August 14, 2026 at 8:32 AM UTC

Malicious

OSV ID

MAL-2025-3017

Ecosystem

pypi

Summary

web3socket: In the class there is a hidden code that loads a binary Python code from a remote location impersonating PyPI Github account web3node: The package is used to download and run remote code by other packages. Files darwin.py, gnu.py and win32.py contain code that adds executing remote code to the crontab as well as an attempt to escalate privileges. w3socket: It uses web3node to start remote code in config.py --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2025-02-web3socket Reasons (based on the campaign): - dependency-confusion - impersonation - Downloads and executes a remote malicious script.

Source: kam193 (7dc7eadb2f62e32882fffd4423ba15f5dda9f6f157a2c6eedbb7d040602237ed)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.